# Linking Rancher to AWS

**URL:** <https://forums.suse.com/t/linking-rancher-to-aws/1924>\
**Category:** Rancher 1.x\
**Created:** [March 2, 2016, 6:02pm UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924 "2016-03-02T18:02:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![siminm](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/siminm/32/66_2.png) [@siminm](https://forums.suse.com/u/siminm)\
**Post date:** [March 2, 2016, 6:02pm UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924/1 "2016-03-02T18:02:46Z")

</div>

I created an IAM account for use with Rancher and gave it, what I think, is sufficient permissions.

Getting an error on this page /infra/hosts/add/amazonec2 :

UnauthorizedOperation: You are not authorized to perform this operation.

What operation is it talking about? Is there documentation/sample on what IAM policy Rancher needs?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 2, 2016, 7:19pm UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924/2 "2016-03-02T19:19:12Z")

</div>

You can open up the browser (preferably Chrome) inspector Networking tab and see what request is failing; The first step after entering credentials is connecting to each region and getting all the VPC/subnets.

So my random guess would be that you didn’t grant permission to every region, and we don’t handle that by only showing the ones that were available?

The UI calls these in the EC2 SDK, I’m not sure the exact IAM names but they should map directly:

```auto
describeRegions
describeSubnets
describeSecurityGroups
createSecurityGroup
authorizeSecurityGroupIngress
createTags

```

and once you actually submit `docker-machine` makes some additional calls, e.g. obviously to create the instance but possibly others.

---

<div class="post-metadata">

**Author:** ![siminm](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/siminm/32/66_2.png) [@siminm](https://forums.suse.com/u/siminm)\
**Post date:** [March 3, 2016, 5:10am UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924/3 "2016-03-03T05:10:05Z")

</div>

Thanks, Vincent. Viewing the console didn’t help at all, but adding the stock AmazonEC2ReadOnlyAccess policy made it work.

Once the setup finalized I got a new block under my “Hosts” tab which quickly fell into Error state with message “You are not authorized to perform this operation.” I think I know why it happened, and I fixed the permission, but how do I re-kick the attempt? Do I have to re create the host with all of the settings I just did?

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [March 3, 2016, 2:49pm UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924/4 "2016-03-03T14:49:38Z")

</div>

Is the clone option existent for your host? If so, then you’d be able to clone it with all the settings.

---

<div class="post-metadata">

**Author:** ![siminm](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/siminm/32/66_2.png) [@siminm](https://forums.suse.com/u/siminm)\
**Post date:** [March 3, 2016, 6:22pm UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924/5 "2016-03-03T18:22:05Z")

</div>

The only option is to remove the host. I even looked at the API directly

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 3, 2016, 6:35pm UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924/6 "2016-03-03T18:35:47Z")

</div>

I’m not sure that there’s actually a good reason why, but we only let you clone machines that worked.

---

<div class="post-metadata">

**Author:** ![siminm](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/siminm/32/66_2.png) [@siminm](https://forums.suse.com/u/siminm)\
**Post date:** [March 3, 2016, 6:54pm UTC](https://forums.suse.com/t/linking-rancher-to-aws/1924/7 "2016-03-03T18:54:39Z")

</div>

You see the issue here? There’s no explanation of what failed, and iterating trying to fix it is extremely high friction. Not to mention that the specified AWS key/secret is logged in plain text in /var/log/syslog
